PT-2023-22624 · Unknown · Guangdong Pythagorean Oa Office System

CVE-2023-3029

·

Published

2023-06-01

·

Updated

2024-05-17

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Guangdong Pythagorean OA Office System versions up to 4.50.31
Description A vulnerability has been found in the Guangdong Pythagorean OA Office System, affecting unknown code of the file /note/index/delete. The manipulation of the id argument leads to cross-site request forgery. The attack can be initiated remotely.
Recommendations For Guangdong Pythagorean OA Office System versions up to 4.50.31, consider disabling access to the /note/index/delete file until a patch is available. Restrict the manipulation of the id argument to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-3029

Affected Products

Guangdong Pythagorean Oa Office System